Malware

Bulz.284902 (B) (file analysis)

Malware Removal

The Bulz.284902 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.284902 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

0.tcp.ngrok.io

How to determine Bulz.284902 (B)?


File Info:

crc32: BBC94BE1
md5: b7ea0a82e1d5b97e04e937db8d53c534
name: B7EA0A82E1D5B97E04E937DB8D53C534.mlw
sha1: 9b4497b5ab0ee954aaf7253622eb709310f26267
sha256: 80c69b997fd06c163790c558ab21ace6d3b04eea1664f97746da10b5de799c29
sha512: 32272439f6a27f4d65bc5be3a75050a63bd3ef9a7f0e2beb6559683d702e30fbad6869daca1cb005263cb7f1a9b57492faf3f24625030721e5c80e958d1245fb
ssdeep: 24576:q2G/nvxW3WwWi81yqUsNuS+jOVdbScqVeW:qbA3K/1RUIT+j4bSd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.284902 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.284902
FireEyeGeneric.mg.b7ea0a82e1d5b97e
CAT-QuickHealTrojan.Wacatac
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Bulz.284902
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34590.ZyZ@aai7@FdO
CyrenW32/Fynloski.JQOL-9129
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Agent-AWZS [Trj]
KasperskyBackdoor.Win32.DarkKomet.aagt
AlibabaBackdoor:Win32/DarkKomet.845f6780
NANO-AntivirusTrojan.Win32.DarkKomet.ecawjb
Ad-AwareGen:Variant.Bulz.284902
SophosML/PE-A
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureHeuristic.HEUR/AGEN.1136694
DrWebBackDoor.Tordev.976
ZillyaTrojan.ScriptKD.JS.10
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
EmsisoftGen:Variant.Bulz.284902 (B)
IkarusBackdoor.Win32.DarkKomet
AviraHEUR/AGEN.1136694
MAXmalware (ai score=89)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet.xyk
MicrosoftTrojan:Win32/Wacatac.D8!ml
ArcabitTrojan.Bulz.D458E6
ZoneAlarmBackdoor.Win32.DarkKomet.aagt
GDataGen:Variant.Bulz.284902
CynetMalicious (score: 100)
VBA32Backdoor.Tordev
ALYacGen:Variant.Bulz.284902
MalwarebytesGeneric.Worm.Autorun.DDS
TencentWin32.Backdoor.Darkkomet.Pijy
SentinelOneStatic AI – Suspicious PE
AVGWin32:Agent-AWZS [Trj]
Cybereasonmalicious.2e1d5b
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.DarkKomet.HgIASPkA

How to remove Bulz.284902 (B)?

Bulz.284902 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment